CVE-2011-4828
AutoSec Tools V-CMS 1.0 - Remote Code Execution via Unrestricted File Upload in Inline Image Upload
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-4828.
PoCs published by Metasploit, AutoSec Tools, sinn3r, including Metasploit module exploits/linux/http/vcms_upload.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in V-CMS 1.0, allowing arbitrary PHP code execution by uploading a malicious file via the inline_image_upload.php endpoint.
Description
Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.
Exploits (2)
This Metasploit module exploits an unauthenticated file upload vulnerability in V-CMS 1.0, allowing arbitrary PHP code execution by uploading a malicious file via the inline_image_upload.php endpoint.
This Metasploit module exploits an unauthenticated file upload vulnerability in V-CMS (CVE-2011-4828) by uploading a malicious PHP file disguised as an image, then executing it via a GET request to achieve remote code execution.